1C Flashcards

1
Q

Q1: The COSO Internal Control – Integrated Framework is the most important IT Governance framework used by companies to demonstrate SOX-compliance.

A

FALSE: COSO is not an IT Governance framework, but a general corporate governance framework.

COBIT-> Most widely accepted standard for demonstrating SOX compliance for IT-centered organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Q2: COBIT makes use of process maturity analysis through a so-called process capability model. All processes of a firm can then become subject to the use of such a capability model in order to assess and improve them.

A

true

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Q3: For both Corporate Goverance, as well as IT Governance, the ultimate responsibility lies with the management of an organization, in other words the team of C-level executives (CEO, CIO, CFO, etc.)

A

False

manager& governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Q4: Section 404 of the Sarbanes-Oxley Act states, amongst other, that all (financial) information can be tracked to its origin.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Q5: The principal agent problem states that

A

he shareholders and management may have different interests.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Q6: In case of deliberate (onopzettelijk) inaccurate information and/or certification, the Sarbanes-Oxley Act may penalize

A

firm and managers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Q7: Which statement about the COSO framework is NOT CORRECT?
* It can be used to become SOX compliant.
* It is named after the Committee of Sponsoring Organizations of the Treadway Commission (IMA, AAA, AICPA, IIA, FEI).
* It s an IT framework.
* It s five key components are: control environment, risk assessment, control activities, information and
communication and monitoring activities

A

It s an IT framework.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Q8: Corporate and IT Governance frameworks are developed by professional organizations such as ISACA and COSO. Accordingly, these frameworks are strongly practice-driven and not, or only limitedly, scientifically validated.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Q9: In COBIT a RACI chart or matrix can be used to

A

assign responsibilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Q10: The Sarbanes-Oxley Act is an American law setting new governance standards for publicly traded companies in the US.

A

true

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Q11: The Sarbanes-Oxley Act aims at -

A

protecting the shareholders of a firm and the public from accounting errors and fraud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Q12: COBIT is one of the most popular IT governance frameworks. Despite the fact that IT is a cornerstone for compliance, reporting, and risk management, organizations are obliged to rely on other frameworks (such as the COSO Internal Control-Integrated Framework) so as to demonstrate SOX compliance.

A

False

cobit most widely accepted standard for demonstrating SOX compliance for IT-centered organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Q13: IS Governance is broadly defined as the capability of an organization to manage and control IT strategy and ensure alignment between business and IT so that value creation improves.

A

true

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Q14: Which of the following is NOT a COBIT governance principle?
* Provide stakeholder value
* Holistic approach
* Tailored to enterprise needs
* Governance indiscernible from management

A
  • Governance indiscernible from management
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Q15: What is NOT a goal of corporate governance?
* Regulate risk
* Reduce opportunity for corruption
* Centralize all responsibilities at the management level
* Maintain legal and ethical standards

A
  • Centralize all responsibilities at the management level -> this
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Q16: Looking back upon the COBIT standard, it can be said it is
* Relatively easy to understand and implement
* Quite challenging and complex to understand and implement

A
  • Quite challenging and complex to understand and implement -> this
17
Q

Q17: coso is an example of
* An internal control framework
* An external control framework
* An internal and external control framework
* Business model

A
  • An internal control framework -> this
18
Q

Q18: Which statement about COBIT is NOT CORRECT?
* It is a Business Framework for Governance and Management of Enterprise IT.
* It s only used by a minority of firms.
* It was developed by by ISACA (https://www.isaca.org).
* It provides a set of tools that ensures IT is working effectively and generates value.

A
  • It s only used by a minority of firms. -> this
19
Q

The most recent version of COBIT was introduced in

A

2019